Indirect Prompt Injection
Indirect prompt injection is an attack in which malicious instructions are hidden in content that an AI system later processes—web pages, documents, emails, tool outputs—hijacking the model's behavior without direct interaction with the attacker.
How Indirect Prompt Injection Works
In direct prompt injection, the attacker sends the malicious prompt to the model themselves. In indirect prompt injection, the attacker plants the malicious content somewhere the AI system will later encounter it: a web page an AI browsing agent will read, a document an AI summarizer will process, a tool output an agent will act on.
The attacker never interacts with the target AI system directly. The victim, an employee using AI to process content, or an agent operating autonomously, triggers the attack by consuming the poisoned content.
Why Indirect Prompt Injection Is a Major Enterprise Concern
Enterprise AI systems, particularly agentic AI, routinely process untrusted content: incoming emails, web search results, retrieved documents, API responses. Any of these can be attacker-controlled. Once the malicious instructions reach the model, the attack can proceed the same way direct prompt injection would, including exfiltrating data, taking unauthorized actions, or bypassing safety controls.
See the security risks of AI agents in the enterprise.
Defenses Against Indirect Prompt Injection
Common defenses include treating all content from untrusted sources as untrusted (not as instructions), applying strict permission scoping so agents cannot take high-impact actions autonomously, monitoring for anomalous agent behavior, and using guardrails that filter for known injection patterns.
Related Terms
Full AI Visibility. Full Control. One Connected Platform.
Enterprise AI is expanding faster than most governance programs can track. Kovrr connects every AI signal across browser, endpoint, network, identity, and vendor systems into a single platform so security, governance, and risk teams work from the same evidence.


